A systematic review on security in Process-Aware Information Systems - Constitution, challenges, and future directions

被引:42
|
作者
Leitner, Maria [1 ]
Rinderle-Ma, Stefanie [1 ]
机构
[1] Univ Vienna, Fac Comp Sci, Res Grp Workflow Syst & Technol, A-1090 Vienna, Austria
关键词
Business Process Management; Business process security; Process-Aware Information Systems; Security; Systematic literature review; Workflow security; ACCESS-CONTROL; AUTHORIZATION CONSTRAINTS; SEMANTIC CONSTRAINTS; BUSINESS PROCESSES; MODEL; CHECKING; SUPPORT; SPECIFICATION; RECOVERY; RBAC;
D O I
10.1016/j.infsof.2013.12.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Context: Security in Process-Aware Information Systems (PAIS) has gained increased attention in current research and practice. However, a common understanding and agreement on security is still missing. In addition, the proliferation of literature makes it cumbersome to overlook and determine state of the art and further to identify research challenges and gaps. In summary, a comprehensive and systematic overview of state of the art in research and practice in the area of security in PAIS is missing. Objective: This paper investigates research on security in PAIS and aims at establishing a common understanding of terminology in this context. Further it investigates which security controls are currently applied in PAIS. Method: A systematic literature review is conducted in order to classify and define security and security controls in PAIS. From initially 424 papers, we selected in total 275 publications that related to security and PAIS between 1993 and 2012. Furthermore, we analyzed and categorized the papers using a systematic mapping approach which resulted into 5 categories and 12 security controls. Results: In literature, security in PAIS often centers on specific (security) aspects such as security policies, security requirements, authorization and access control mechanisms, or inter-organizational scenarios. In addition, we identified 12 security controls in the area of security concepts, authorization and access control, applications, verification, and failure handling in PAIS. Based on the results, open research challenges and gaps are identified and discussed with respect to possible solutions. Conclusion: This survey provides a comprehensive review of current security practice in PAIS and shows that security in PAIS is a challenging interdisciplinary research field that assembles research methods and principles from security and PAIS. We show that state of the art provides a rich set of methods such as access control models but still several open research challenges remain. (C) 2013 The Authors. Published by Elsevier B.V. All rights reserved.
引用
收藏
页码:273 / 293
页数:21
相关论文
共 50 条
  • [1] On the Modeling and Verification of Security-Aware and Process-Aware Information Systems
    Crampton, Jason
    Huth, Michael
    [J]. BUSINESS PROCESS MANAGEMENT WORKSHOPS, PT II, 2012, 100 : 423 - +
  • [2] Schema Evolution in Object and Process-Aware Information Systems: Issues and Challenges
    Chiao, Carolina Ming
    Kuenzle, Vera
    Reichert, Manfred
    [J]. BUSINESS PROCESS MANAGEMENT WORKSHOPS (BPM), 2013, 132 : 328 - 339
  • [3] Time patterns for process-aware information systems
    Andreas Lanz
    Barbara Weber
    Manfred Reichert
    [J]. Requirements Engineering, 2014, 19 : 113 - 141
  • [4] Process-Aware Information Systems for Emergency Management
    de Leoni, Massimiliano
    Marrella, Andrea
    Russo, Alessandro
    [J]. TOWARDS A SERVICE-BASED INTERNET: SERVICEWAVE 2010 WORKSHOPS, 2011, 6569 : 50 - +
  • [5] Time patterns for process-aware information systems
    Lanz, Andreas
    Weber, Barbara
    Reichert, Manfred
    [J]. REQUIREMENTS ENGINEERING, 2014, 19 (02) : 113 - 141
  • [6] Patterns for Process Edification in Process-aware Information Systems
    Yadav, Vrinda
    Roy, Suman
    Joshi, Rushikesh K.
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (IEEE SCC 2018), 2018, : 161 - 168
  • [7] Mining and Simulation for Process-Aware Information Systems
    Brito e Abreu, Fernando
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING (CAISE 2022), 2022, : 557 - 559
  • [8] Robust and Reliable Process-Aware Information Systems
    Schwerz, Andre Luis
    Liberato, Rafael
    Pu, Calton
    Ferreira, Joao Eduardo
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2021, 14 (03) : 820 - 833
  • [9] VIVACE: A framework for the systematic evaluation of variability support in process-aware information systems
    Ayora, Clara
    Torres, Victoria
    Weber, Barbara
    Reichert, Manfred
    Pelechano, Vicente
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2015, 57 : 248 - 276
  • [10] Predictive compliance monitoring in process-aware information systems: State of the art, functionalities, research directions
    Rinderle-Ma, Stefanie
    Winter, Karolin
    Benzin, Janik-Vasily
    [J]. INFORMATION SYSTEMS, 2023, 115